nagios
301 tracked vulnerabilities.
CVE-2020-6584
MEDIUM
Nagios Log Server 2.1.3 - Improper Privilege Management
Mar 16, 2020
CVSS 6.5
EPSS 0.00
CVE-2019-3698
MEDIUM
nagios < 3.5.1 - Local Privilege Escalation via Symlink Race in Cronjob
Feb 28, 2020
CVSS 5.7
EPSS 0.00
CVE-2019-20197
HIGH
Nagios XI 5.6.9 - Authenticated OS Command Injection via schedulereport.php id Parameter
Dec 31, 2019
CVSS 8.8
EPSS 0.36
CVE-2019-20139
MEDIUM
Nagios XI 5.6.9 - Authenticated Cross-Site Scripting via nocscreenapi.php or schedulereport.php Parameters
Dec 30, 2019
CVSS 5.4
EPSS 0.06
CVE-2019-15949
HIGH
KEV
Nagios XI < 5.6.6 - Authenticated Remote Command Execution via getprofile.sh
Sep 05, 2019
CVSS 8.8
EPSS 0.88
CVE-2019-15898
MEDIUM
Nagios Log Server < 2.0.8 - Reflected Cross-Site Scripting via Login Page Username
Sep 03, 2019
CVSS 6.1
EPSS 0.04
CVE-2019-12279
CRITICAL
Nagios XI 5.6.1 - SQL Injection via Username Parameter in Password Reset Form
May 22, 2019
CVSS 9.8
EPSS 0.16
CVE-2019-9167
MEDIUM
Nagios XI < 5.5.11 - Cross-Site Scripting via xiwindow Parameter
Mar 28, 2019
CVSS 6.1
EPSS 0.14
CVE-2019-9166
HIGH
Nagios XI < 5.5.11 - Privilege Escalation via Config File Manipulation
Mar 28, 2019
CVSS 7.8
EPSS 0.00
CVE-2019-9204
CRITICAL
Nagios IM < 2.2.7 - SQL Injection
Mar 28, 2019
CVSS 9.8
EPSS 0.04
CVE-2019-9203
CRITICAL
Nagios Incident Manager < 2.2.7 - Authorization Bypass via API
Mar 28, 2019
CVSS 9.8
EPSS 0.05
CVE-2019-9202
HIGH
Nagios IM <2.2.7 - Authenticated RCE
Mar 28, 2019
CVSS 8.8
EPSS 0.43
CVE-2019-9165
CRITICAL
Nagios XI < 5.5.11 - SQL Injection via Fusekeys API
Mar 28, 2019
CVSS 9.8
EPSS 0.06
CVE-2019-9164
HIGH
Nagios XI < 5.5.11 - Authenticated Remote Code Execution via Autodiscovery Job
Mar 28, 2019
CVSS 8.8
EPSS 0.62
CVE-2018-25123
HIGH
Nagios XI <5.5.7 - Privilege Escalation
Oct 30, 2025
CVSS 7.8
EPSS 0.00
CVE-2018-25122
HIGH
Nagios XI < 5.4.13 - Authenticated Remote Code Execution via Component Download Page
Oct 30, 2025
CVSS 8.8
EPSS 0.01
CVE-2018-25121
MEDIUM
Nagios XI < 5.4.13 - Stored Cross-Site Scripting via Views Page
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2018-25119
MEDIUM
Nagios Fusion < 4.1.5 - Cross-Site Scripting via Fusionwindow Parameter
Oct 30, 2025
CVSS 6.1
EPSS 0.00
CVE-2018-17147
MEDIUM
Nagios XI < 5.5.4 - Cross-Site Scripting in Auto Login Admin Management Page
Jul 10, 2019
CVSS 4.8
EPSS 0.03
CVE-2018-17148
CRITICAL
Nagios XI < 5.5.4 - Insufficient Access Control in Configuration Snapshot Page
Jun 19, 2019
CVSS 9.8
EPSS 0.00
CVE-2018-17146
MEDIUM
Nagios XI < 5.5.4 - Stored Cross-Site Scripting via Account Information Name Parameter
Jun 19, 2019
CVSS 5.4
EPSS 0.03
CVE-2018-20172
MEDIUM
Nagios XI < 5.5.8 - Cross-Site Scripting via rss_url Parameter
Dec 17, 2018
CVSS 6.1
EPSS 0.04
CVE-2018-20171
MEDIUM
Nagios XI < 5.5.8 - Cross-Site Scripting via RSS Dashlet URL Parameter
Dec 17, 2018
CVSS 6.1
EPSS 0.04
CVE-2018-18245
MEDIUM
Nagios Core 4.4.2 - Cross-Site Scripting via Alert Summary Reports
Dec 17, 2018
CVSS 5.4
EPSS 0.05
CVE-2018-15714
MEDIUM
Nagios XI 5.5.6 - Unauthenticated Reflected Cross-Site Scripting via oname and oname2 Parameters
Nov 14, 2018
CVSS 6.1
EPSS 0.21
Products
nagios_xi 192
nagios 37
log_server 23
fusion 19
network_analyzer 7
nagios_core 5
XI 3
incident_manager 3
plugins 3
remote_plug_in_executor 3
Log Server 2
Nagios XI 2
favorites 2
nagios_cross_platform_agent 2
business_process_intelligence 1
nagios_network_analyzer 1
nagios_xi_docker_wizard 1
nagios_xi_switch_wizard 1
nagios_xi_watchguard_wizard 1
ndoutils 1
remote_plugin_executor 1
Quick Filters